unjs / redirect-ssl

Connect/Express middleware to enforce https using is-https
MIT License
100 stars 15 forks source link

chore(deps): update devdependency pem to v1.13.2 [security] #18

Closed renovate[bot] closed 5 years ago

renovate[bot] commented 5 years ago

This PR contains the following updates:

Package Type Update Change
pem devDependencies patch 1.13.1 -> 1.13.2

GitHub Vulnerability Alerts

GHSA-pgcr-7wm4-mcv6 / WS-2018-0204

Versions of pem before 1.13.2 expose sensitive data when the readPkcs12 is used.


Release Notes

Dexus/pem ### [`v1.13.2`](https://togithub.com/Dexus/pem/blob/master/CHANGELOG.md#​1140httpsgithubcomDexuspemcomparev1132v1140-2019-01-25) [Compare Source](https://togithub.com/Dexus/pem/compare/v1.13.1...v1.13.2) ##### Features - **package:** Support SAN Certificate from CSR ([#​229](https://togithub.com/Dexus/pem/issues/229)) ([fa450f5](https://togithub.com/Dexus/pem/commit/fa450f5)) #### [1.13.2](https://togithub.com/Dexus/pem/compare/v1.13.1...v1.13.2) (2018-10-26) ##### Bug Fixes - **package:** security fix ([#​217](https://togithub.com/Dexus/pem/issues/217)) ([bed1190](https://togithub.com/Dexus/pem/commit/bed1190)) #### [1.13.1](https://togithub.com/Dexus/pem/compare/v1.13.0...v1.13.1) (2018-09-14) ##### Bug Fixes - **package:** remove -utf8 option ([4d10fb2](https://togithub.com/Dexus/pem/commit/4d10fb2)), closes [#​214](https://togithub.com/Dexus/pem/issues/214)

Renovate configuration

:date: Schedule: "" (UTC).

:vertical_traffic_light: Automerge: Disabled by config. Please merge this manually once you are satisfied.

:recycle: Rebasing: Whenever PR becomes conflicted, or if you modify the PR title to begin with "rebase!".

:no_bell: Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Renovate Bot. View repository job log here.